This Already Happened

Real People.
Real Money. Gone.

Reported FY 25-26 cases from India — not hypotheticals. Each one names a real technique fraudsters used, and the specific layer of NonaShield built to catch it.

UPI Collect-Request Scam · Pune

"Scan to Receive" — Except It Pays Out Instead.

A Pune resident selling an item on OLX was told by the "buyer" to scan a QR code and enter his UPI PIN to receive the payment. Entering a PIN never receives money on UPI — it only ever authorises an outgoing payment. ₹47,000 left his HDFC account instantly, and the buyer was gone.

Source: Business Standard →
Why It Worked

The confusion is by design — most people don't know that a UPI PIN only ever authorises payment out, never in. By the time the app's own confirmation screen appears, the transaction is one tap from irreversible.

The NonaShield Layer

This is what a predictive pre-transaction gate is for — scoring device and session risk before the transaction executes, flagging a high-risk pattern (a first-time payee, an unusual context) before PIN entry rather than after. The resulting hash-chained evidence record also settles the "what did I actually authorise" dispute after the fact.

See the Agentic AI Advisory Brief →
Voice Cloning / Deepfake · Reported Nationwide Pattern

The Voice Was His Son's. It Wasn't His Son.

A pattern documented across multiple reports: a parent gets a call, or a short glitchy video call, and the voice sounds exactly like their child — in a sudden accident, an arrest, a hospital. A cloned voice needs only a few seconds of audio, often lifted straight from a public social media clip. The ask is always the same — money moved immediately, before there's time to check.

Source: Caller Digital →
Why It Worked

The victim is a genuine customer, on their own enrolled device, moving their own money — willingly, if under manufactured panic. No cryptographic check is designed to catch this, because nothing about the transaction's mechanics is wrong.

The NonaShield Layer

The behavioural layer has a named category for exactly this — Coercion-Specific detection for digital-arrest and romance-scam-style pressure — watching for the session-level signs of duress rather than trusting that a correctly-signed transaction means a willing one. It's the same honest admission this platform makes everywhere else: possession proof can't stop this; surgical behavioural friction has to.

See the Coercion-Detection Case Study →
VPN-Masked Fraud Ring · Delhi

Handlers in Cambodia. Mule Accounts Everywhere.

Delhi Police's cyber cell busted an interstate investment-fraud syndicate run through VPNs and foreign servers, with handlers operating out of Cambodia and links to more than 35 separate complaints. Indian cyber police have separately estimated that roughly one in three major cyber-fraud cases now trace back to overseas infrastructure.

Source: All India Radio News →
Why It Worked

A VPN makes a connection from Cambodia look like it's coming from anywhere the fraudster chooses. Systems that trust an IP address for location or reputation checks have nothing left to check once that address is rented, not real.

The NonaShield Layer

This is what network and edge analysis is for — ASN reputation blocking and VPN/proxy detection at the edge, plus GPS-vs-IP cross-checks that catch a device claiming to be somewhere its actual network path contradicts. The IP alone was never the trust signal; where it disagrees with everything else is.

See the Network Analysis Brief →
Banking Trojan Malware · Mumbai

It Was Just a PDF Reader. It Wasn't Just a PDF Reader.

A Mumbai businessman downloaded what looked like an ordinary PDF reader app. It was a banking trojan — logging his keystrokes and silently capturing one-time passwords as they arrived. Eleven transactions later, ₹38 lakh had moved out of his business account.

Source: Cybernews →
Why It Worked

A sideloaded app, installed outside the Play Store, with permissions to read notifications and SMS — nothing about that requires rooting the phone, so a check that only looks for root or jailbreak state misses it entirely.

The NonaShield Layer

RASP's Tamper, Repackaging & SDK Self-Integrity and Hooking Framework detection categories catch this class of compromise directly, and the device fingerprint's own installer-source field flags that the app arrived from outside the Play Store in the first place — a fact the OS knows and most banking apps never ask it.

See the RASP Case Study →
Remote-Access App Fraud · Mumbai

Told to Install an App to "Pay an Electricity Bill."

A senior citizen doctor in Mumbai received a call from someone posing as a utility representative, who talked him into installing a remote-access app to "process" a bill payment. Once installed, the caller could see everything on his screen — including one-time passwords as they arrived. Eighteen transactions later, close to ₹9 lakh had moved out across two credit cards and a debit card. The RBI has separately warned banks about this exact pattern.

Source: Moneylife →
Why It Worked

A remote-access session isn't malware in the traditional sense — the victim installed it willingly. Most banking apps have no way to tell "I'm being viewed and controlled by someone else right now" from a normal session.

The NonaShield Layer

This is a named detection category in the RASP layer — Screen-Share, Overlay & UI Attacks — checked as part of the 100+ on-device vectors every session. An active screen-mirroring or remote-control session is a detectable device state, independent of whether the app installed was "legitimate" software like a remote-access tool.

See the RASP Case Study →
SIM Swap · Bengaluru, June 2026

No Call, No Link, No Click — ₹7.2 Lakh Gone Anyway.

Business Today · Trends
"No call, no link, no Clue: This Bengaluru youth loses ₹7.2 lakh in SIM-swap fraud"
Cybersecurity experts confirmed the fraudsters moved his mobile number onto a different SIM entirely without his knowledge.

A Bengaluru resident's mobile number was quietly moved onto a SIM card he never held — no phishing link clicked, no call answered. Once the fraudsters controlled his number, they intercepted the one-time passwords his bank sent for verification and drained his account, without him doing anything wrong at all.

Source: Business Today →
Why It Worked

An OTP sent by SMS is only as trustworthy as the SIM it lands on. Once the number itself is stolen, the OTP arrives at the fraudster's phone — a perfectly valid code, on the wrong device entirely.

The NonaShield Layer

This is precisely what hardware-bound identity is for. The signing key that authorises a transaction lives inside the original device's own security chip — it does not move with a phone number to a new SIM or a new phone. A SIM swap gets the fraudster the OTP channel; it does not get them the key. No key, no valid signature, no transaction.

See How Fingerprint Verifies the Device →
Loan-App Fraud · Nationwide

One Phone. Many Names. Loans Nobody Approved.

India's RTI Help Desk · Consumer Guide
Loan app harassment in India — stop abuse and complain in 2026
A running consumer-guidance resource tracking harassment complaints against illegal digital lending apps, and how to report them.

Beyond the fake apps themselves — which regulators have been blocking by the hundreds — a related pattern hits real lenders directly: the same device, sometimes the same fraud ring, applying for credit under multiple fabricated identities before any human underwriter sees a pattern. Regulatory reporting has linked loan-app-related extortion to over 100 deaths between 2022 and 2024 — a reminder that this isn't a victimless numbers game.

Source: Right to Information Wiki →
Why It Worked

A name, a PAN, and a photo are all easy to fabricate or steal. Underwriting systems built to check identity documents have no way to notice that the phone submitting the tenth application this week is the same phone that submitted the first nine — under nine different names.

The NonaShield Layer

Device fingerprinting exists for exactly this: a stable, hardware-anchored device identity that survives app reinstalls and cleared data, so a lender can catch one device applying under many names before disbursal — not after the money is already gone and the harassment has already begun.

See the Banking & NBFC Lending Solution →
Fake Trading App · Mysuru

₹1.77 Crore Into an App That Was Never Real.

A Mysuru resident was added to a WhatsApp group promoting a trading app called "Polen Capital." Small early withdrawals worked, building confidence — then larger deposits stopped coming back at all. He lost ₹1.77 crore to an app with a real-looking dashboard and no real broker behind it.

Source: Deccan Herald →
Why It Worked

The app's interface was the entire con — a real-looking balance, a real-looking chart, no real exchange underneath any of it. Nothing about the victim's device was compromised; the fake was the product itself.

The NonaShield Layer

For a genuine broker protecting its real customers, this cuts the other way: APK certificate fingerprinting and tamper detection confirm a customer is running the broker's actual signed app, not a repackaged clone — and the same device identity that catches loan-stacking also flags a device pattern seen across other reported scam apps.

See the Fingerprinting Technical Brief →
Task-Based Job Scam · Hyderabad

Liking Videos Paid ₹200 a Day. Then It Asked for ₹51 Lakh.

An engineer was recruited over Telegram for a "work from home" job — liking videos, rating listings, small tasks with instant payouts. The trust built over days of tiny real payments was the setup: he was gradually walked into depositing larger and larger sums for "bonus tasks" that never paid out, losing ₹51 lakh in total.

Source: The Hans India →
Why It Worked

Every individual transfer looked like ordinary behaviour from a trusted device — the victim's own phone, sending money the victim chose to send. The tell isn't any single transaction; it's the escalating pattern across all of them.

The NonaShield Layer

This is what a per-device behavioural baseline is built to catch — a session-and-transaction pattern (rapid escalation, an entirely new payee category, timing that doesn't match the device's own history) flagged as anomalous even though every individual step looks clean.

See the Agentic AI Advisory Brief →
Fake KYC Update Link · K.R. Puram

One WhatsApp Link. ₹9.96 Lakh Gone.

A 71-year-old received a WhatsApp message warning that his nationalised bank account would be blocked unless he updated his KYC immediately. The panic-inducing link led him to a fake verification page — and from there, ₹9.96 lakh out of his account.

Source: Country and Politics →
Why It Worked

Urgency plus an official-looking bank name is usually enough. The link itself often leads to a sideloaded app or a credential-harvesting page dressed up as the bank's own KYC portal.

The NonaShield Layer

The same fingerprinting fields that catch banking trojans apply here — installer source and APK certificate checks flag anything sideloaded outside the Play Store as exactly that, before it gets anywhere near a real session.

See the Fingerprinting Technical Brief →
Being Honest About This

None of these cases had NonaShield running on the app in question — that's not a claim we can make either way, since it isn't public information. What we can say precisely is which named, documented layer of the platform was built for each pattern, and why. Software can't undo a transfer that's already settled; the point is catching the pattern before it does.

See the Layer That Would Have Caught This.